CVE-2022-22707

Name
CVE-2022-22707
Description
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 bytes representing -1), as demonstrated by remote denial of service (daemon crash) in a non-default configuration. The non-default configuration requires handling of the Forwarded header in a somewhat unusual manner. Also, a 32-bit system is much more likely to be affected than a 64-bit system.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://redmine.lighttpd.net/issues/3134
DEBIAN https://www.debian.org/security/2022/dsa-5040

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:lighttpd:lighttpd:*:*:*:*:*:*:*:* lighttpd >= 1.4.46 <= 1.4.63

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
lighttpd 3.14-main 1.4.59-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
lighttpd 3.13-main 1.4.57-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
lighttpd 3.12-main 1.4.55-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
lighttpd edge-main 1.4.64-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
lighttpd 3.15-main 1.4.64-r0 Natanael Copa <ncopa@alpinelinux.org> fixed